CVE CRITICAL CVE-2025-68665

LangChain is a framework for building LLM-powered applications. Prior to @langchain/core versions 0.3.80 and 1.1.8, and prior to langchain versions 0.3.37 and 1.2.3, a serialization injection vulnerability exists

CVSS 9.1 langchain.js View details
CVE CRITICAL CVE-2024-46946

langchain_experimental (aka LangChain Experimental) 0.1.17 through 0.3.0 for LangChain allows attackers to execute arbitrary code through sympy.sympify (which uses eval) in LLMSymbolicMathChain. LLMSymbolicMathChain was introduced in fcccde406dd9e9b05fc9babcbeb9ff527b0ec0c6

CVSS 9.8 langchain-experimental View details
CVE CRITICAL CVE-2024-27444

langchain_experimental (aka LangChain Experimental) in LangChain before 0.1.8 allows an attacker to bypass the CVE-2023-44467 fix and execute arbitrary code via the __import__, __subclasses__, __builtins__, __globals__, __getattribute

CVSS 9.8 langchain-experimental View details
CVE CRITICAL CVE-2023-44467

langchain_experimental (aka LangChain Experimental) in LangChain before 0.0.306 allows an attacker to bypass the CVE-2023-36258 fix and execute arbitrary code via __import__ in Python code, which

CVSS 9.8 langchain_experimental View details
CVE CRITICAL CVE-2025-46059

langchain-ai v0.3.51 was discovered to contain an indirect prompt injection vulnerability in the GmailToolkit component. This vulnerability allows attackers to execute arbitrary code and compromise the application

CVE CRITICAL CVE-2025-2828

Server-Side Request Forgery (SSRF) vulnerability exists in the RequestsToolkit component of the langchain-community package (specifically, langchain_community.agent_toolkits.openapi.toolkit.RequestsToolkit) in langchain-ai/langchain version 0.0.27. This vulnerability occurs because the toolkit

CVSS 10.0 langchain View details
CVE CRITICAL CVE-2024-2057

vulnerability was found in LangChain langchain_community 0.0.26. It has been classified as critical. Affected is the function load_local in the library libs/community/langchain_community/retrievers/tfidf.py of the component TFIDFRetriever. The manipulation

CVSS 9.8 langchain View details
CVE CRITICAL CVE-2023-39659

issue in langchain langchain-ai v.0.0.232 and before allows a remote attacker to execute arbitrary code via a crafted script to the PythonAstREPLTool._run component

CVSS 9.8 langchain View details
CVE CRITICAL CVE-2026-27966

Agent node in Langflow hardcodes `allow_dangerous_code=True`, which automatically exposes LangChain’s Python REPL tool (`python_repl_ast`). As a result, an attacker can execute arbitrary Python

CVSS 9.8 langflow View details
CVE CRITICAL CVE-2025-45150

Insecure permissions in LangChain-ChatGLM-Webui commit ef829 allows attackers to arbitrarily view and download sensitive files via supplying a crafted request

CVSS 9.8 langchain-chatglm-webui View details
CVE CRITICAL CVE-2025-6853

vulnerability classified as critical has been found in chatchat-space Langchain-Chatchat up to 0.3.1. This affects the function upload_temp_docs of the file /knowledge_base/upload_temp_docs of the component Backend

CVSS 9.8 langchain-chatchat View details
CVE CRITICAL CVE-2024-8309

vulnerability in the GraphCypherQAChain class of langchain-ai/langchain version 0.2.5 allows for SQL injection through prompt injection. This vulnerability can lead to unauthorized data manipulation, data exfiltration, denial

CVSS 9.8 langchain View details
CVE CRITICAL CVE-2024-7774

path traversal vulnerability exists in the `getFullPath` method of langchain-ai/langchainjs version 0.2.5. This vulnerability allows attackers to save files anywhere in the filesystem, overwrite existing text files, read

CVSS 9.1 langchain.js View details
CVE CRITICAL CVE-2024-7042

vulnerability in the GraphCypherQAChain class of langchain-ai/langchainjs versions 0.2.5 and all versions with this class allows for prompt injection, leading to SQL injection. This vulnerability permits unauthorized data

CVSS 9.8 langchain View details
CVE CRITICAL CVE-2023-32785

Langchain SQL Injection vulnerability

CVSS 9.8 langchain View details
CVE CRITICAL CVE-2023-39631

issue in LanChain-ai Langchain v.0.0.245 allows a remote attacker to execute arbitrary code via the evaluate function in the numexpr library

CVSS 9.8 langchain View details
CVE CRITICAL CVE-2023-36281

issue in langchain v.0.0.171 allows a remote attacker to execute arbitrary code via a JSON file to load_prompt. This is related to __subclasses__ or a template

CVSS 9.8 langchain View details
CVE CRITICAL CVE-2023-38896

issue in Harrison Chase langchain v.0.0.194 and before allows a remote attacker to execute arbitrary code via the from_math_prompt and from_colored_object_prompt functions

CVSS 9.8 langchain View details
CVE CRITICAL CVE-2023-38860

issue in LangChain v.0.0.231 allows a remote attacker to execute arbitrary code via the prompt parameter

CVSS 9.8 langchain View details
CVE CRITICAL CVE-2023-36095

issue in Harrison Chase langchain v.0.0.194 allows an attacker to execute arbitrary code via the python exec calls in the PALChain, affected functions include from_math_prompt and from_colored

CVSS 9.8 langchain View details
Page 1 of 2 Next